官术网_书友最值得收藏!

Planning and reconnaissance

In the planning and reconnaissance phase, we define the scope of the penetration test. This initial phase requires a lot of planning, and you need to answer questions, such as:

  • What is the scope of the pentest?
  • What are the restricted URLs?
  • What are the various subdomains in scope?
  • Are there multiple applications hosted on the same domain in different folders?
  • Are there any other platforms where this application is hosted (that is, mobile applications, web applications, desktop applications, and so on)

Once you have answered these questions, you will get some clarity on what is to be tested and what's not. Depending on whether it is a black box or a white box test, further enumeration takes places. In either of the cases, we will have to go ahead and discover all the files and folders of the application in scope and identify the endpoints. Later, in the next chapter, we will see how to discover new files and folders using Burp.

主站蜘蛛池模板: 德安县| 岫岩| 龙岩市| 道真| 江孜县| 桂东县| 丰县| 宜宾市| 四平市| 乡城县| 定边县| 高邮市| 崇左市| 新竹市| 阿拉善右旗| 屏东县| 建德市| 泗洪县| 五大连池市| 平远县| 腾冲县| 贡嘎县| 和田县| 延庆县| 玛多县| 涟水县| 东海县| 柳林县| 伊宁市| 惠州市| 荥经县| 安化县| 柳江县| 上虞市| 芷江| 广水市| 东台市| 河间市| 通辽市| 张家港市| 芦溪县|